ClawAudit verdict

video-podcast-maker

88
🟢 Trusted
Low risk — reviewed by ClawAudit, behavior matches stated purpose

This skill creates video podcasts by researching topics, generating scripts, synthesizing TTS audio, and rendering with Remotion, all documented behavior consistent with its stated automated video podcast creation purpose.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
100
transparency
100
maintenance

Findings (11)

Pattern match critical

Possible hardcoded credential

README_CN.md · code · TOKEN="your-volcengine-access-token

Pattern match high

References sudo — requests elevated privileges

README_CN.md · code · sudo

Pattern match medium

Instructs covert action — may act without user awareness

SKILL.md · prose · downgraded · silently

Pattern match medium

subprocess execution — runs system commands from Python

generate_shorts.py · prose · downgraded · subprocess.run(

Pattern match medium

Long base64 string (100+ chars) — likely obfuscated payload

package.json · prose · downgraded · a6b2f7906b721bba3d67d4aff083df04dad64c399707841b7acf00f6b133b7ac24255f2652fa22ae

Pattern match medium

Accesses shell history/config

README_CN.md · prose · downgraded · ~/.zshrc

Pattern match low

References agent configuration files

SKILL.md · prose · downgraded · CLAUDE.md

Pattern match low

Python os.environ.get — reads environment variable

generate_tts.py · prose · downgraded · os.environ.get(

Pattern match low

Python shutil file operation — copies/moves/deletes files

learn_design.py · prose · downgraded · shutil.rmtree(

Pattern match low

Python urllib.request — network access

onyx_data/deployment/docker-compose.yml · prose · downgraded · urllib.request

Pattern match low

POSTs data to external URL

tts/backends/openai_tts.py · prose · downgraded · .post( "https://

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class B/D/F). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

Requires 4 system binaries.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API